s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.bqtlock

📛 Threat Title

Malware family: BQTlock

Category: BQTlock First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.bqtlock`. Printable name: BQTlock.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.bqtlock VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bqtlock

IOC database

Type
domain
Value
elf.bqtlock
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.bqtlock

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bqtlock

References (1)

Remediations (10)

  • web:any.run

    Explore how BQTLock and GREENBLOOD ransomware operate, why they threaten businesses, and how ANY.RUN helps detect attacks earlier.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as BQTLock .

  • web:cyberpress.org

    Incident Response: Establish clear response protocols for ransomware attacks. Quick containment and remediation can limit downtime and reduce the financial impact of an attack. BQTLock and GREENBLOOD highlight the increasing sophistication of ransomware attacks, where speed, stealth, and data exfiltration are used to amplify damage.

  • web:cybersecuritynews.com

    A sophisticated new ransomware strain named BQTLOCK has emerged in the cyberthreat landscape since mid-July 2025, operating under a comprehensive Ransomware-as-a-Service (RaaS) model that democratizes access to advanced encryption capabilities for cybercriminals. The malware , associated with 'ZerodayX', the alleged leader of the pro-Palestinian hacktivist group Liwaa Mohammed, represents a ...

  • web:medium.com

    BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration ...

  • web:redpiranha.net

    Updated Malware Signatures (Week 1 - January 2026) ... BQTLock Ransomware BQTLock is a ransomware family that emerged in mid-2025 and operates as a Ransomware-as-a-Service (RaaS) platform. It uses hybrid encryption, combining AES-256 for files with RSA-4096 for key protection, and appends the ". bqtlock " extension to encrypted files.

  • web:socradar.io

    A ransomware family with no name—until now. This white paper provides the first comprehensive analysis of BQTLock , an emerging ransomware operation that's been active since early 2024 but remained off the radar due to its evasive tactics and lack of branding.

  • web:www.cyfirma.com

    Deploy a unified threat management strategy - including malware detection, deep learning neural networks, and anti-exploit technology - combined with vulnerability and risk mitigation processes.

  • web:www.pcrisk.com

    What kind of malware is BQTLOCK ? BQTLOCK is ransomware designed to prevent victims from accessing/using their files by encrypting them. In addition to locking data, the ransomware appends its extension (". BQTLOCK ") to files and provides a ransom note (" READ_ME-NOW_2526968.txt "). Here is an example of how BQTLOCK renames files: it changes " 1.jpg " to " 1.jpg. BQTLOCK ", " 2.png " to " 2.png ...

  • web:www.ransomlook.io

    BQTLock surfaced in July 2025 and operates as a fully-fledged Ransomware-as-a-Service (RaaS) with a double-extortion model. It employs AES-256 for file encryption, with keys secured by RSA-4096, appending the . BQTLOCK extension to encrypted files.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.